Sign inSign up
Node.js

dhi.io/node

Node.js 22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

22-alpine-fips-dev, 22-alpine3.24-fips-dev, 22.23-alpine-fips-dev, 22.23-alpine3.24-fips-dev, 22.23.2-alpine-fips-dev, 22.23.2-alpine3.24-fips-dev

Index digest:

sha256:a6e0fa0d744842938788e111cd8f6b51d8e1a61c1bc7b308cc327cc84f6ba092

Manifest digest:

sha256:d332757197f325a6e6fbf6ed4174dd7cb359938d1a5ace4f787a5b7982ce6f1e

Size

47.55 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Apr 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/node:22-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/node:22-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/node@sha256:d7116f44249ad24ba643108ba60ae2b901d06ecbbf3516cb918734f7d09d0498
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/node@sha256:a634d0115c5fdd22d16872f88fb1dd08ddc11f1b9575c700339a08128008d07c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/node@sha256:55a21904e036d0e0f45634fc378b25fd73e8c6e24763e04418ced15176a1b213
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/node@sha256:9e0c8ac2e25261b7d17d0bc27d6209e63fefdd04db76a6a21e37254b1e53daaa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/node@sha256:4f96a1145ed10a721298ed7db2def837808ca2f23b7395243425bd878b5ed5ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/node@sha256:24f14c75b356f239f437528a5b4e9d6a61667eff3577cb232a1d2149b64e2540
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/node@sha256:7258ada2a22bd283e48fcfa7269ccfe692a2f64d0b6ba75bc38cae172add4815
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/node@sha256:cdcb45f1487e78c948217e8fce7ca63b517cc3e240d6a68b8a62e5920e7c43a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/node@sha256:89286b4ec068267bdbf46bf589bbade987a15e635026d7caef1d086f5d4ba3ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/node@sha256:03497d6a36bc948382936bf43c45968a13449fe80a6883992f3f3509b412ef93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/node@sha256:cf13c0f5fcadc764f3b68f6cfcea430209841245ddfdaa6b27720cc1e8e320eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/node@sha256:28c6a75d514b851a3661b64eafc094d8d78ff804839d1e19221014e6b6119ed1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/node@sha256:7bf2429c4d688ad9ecd1e0c769e965f6e1647759367a866277fc84fe13f99fc6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/node@sha256:c7550cd55653792826c1c974ebb87afc08510f308cae97d5b26bef99875e886a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/node@sha256:cbf19676dad80ee6ec94c81591bc5f5d7170b40ff5efc18491de8329462350b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/node@sha256:9037f84ddb086e4b9ae0fc64832d3a58fa8cc5d7fd6aeedaa5273109dc5230aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/node@sha256:3332379cbee78d03c3bcc0f218dc708127bed70550ad6ee767892764fad9e777